2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26872 | HIGH | 8.8 | 0.8% | Jan 30, 2023 | AMI Megarac Password reset interception via API |
| CVE-2022-38451 | HIGH | 7.5 | 2.1% | Jan 30, 2023 | A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially craf... |
| CVE-2022-2988 | HIGH | 7.5 | 0.4% | Jan 30, 2023 | A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a mali... |
| CVE-2022-46359 | HIGH | 8.8 | 0.2% | Jan 30, 2023 | Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary... |
| CVE-2022-46358 | HIGH | 8.8 | 0.2% | Jan 30, 2023 | Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary... |
| CVE-2022-46357 | HIGH | 8.8 | 0.2% | Jan 30, 2023 | Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary... |
| CVE-2022-46356 | HIGH | 8.8 | 0.2% | Jan 30, 2023 | Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary... |
| CVE-2022-25967 | HIGH | 8.8 | 2.0% | Jan 30, 2023 | Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine co... |
| CVE-2022-25936 | HIGH | 7.5 | 1.3% | Jan 30, 2023 | Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the fi... |
| CVE-2022-48285 | HIGH | 7.3 | 1.4% | Jan 29, 2023 | loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive. |
| CVE-2022-4205 | HIGH | 7.5 | 0.6% | Jan 27, 2023 | In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash. |
| CVE-2022-39812 | HIGH | 7.5 | 1.0% | Jan 27, 2023 | Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthentica... |
| CVE-2022-48116 | HIGH | 7.2 | 1.4% | Jan 27, 2023 | AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.in... |
| CVE-2022-4139 | HIGH | 7.8 | 0.3% | Jan 27, 2023 | An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memor... |
| CVE-2022-48073 | HIGH | 7.5 | 0.5% | Jan 27, 2023 | Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext. |
| CVE-2022-48072 | HIGH | 7.8 | 0.9% | Jan 27, 2023 | Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the a... |
| CVE-2022-48071 | HIGH | 7.5 | 0.4% | Jan 27, 2023 | Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext. |
| CVE-2022-48070 | HIGH | 7.8 | 0.9% | Jan 27, 2023 | Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the... |
| CVE-2022-48069 | HIGH | 7.5 | 1.4% | Jan 27, 2023 | Totolink A830R V4.1.2cu.5182 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter. |
| CVE-2022-44715 | HIGH | 8.8 | 0.7% | Jan 27, 2023 | Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions v... |
| CVE-2022-2712 | HIGH | 7.5 | 0.9% | Jan 27, 2023 | In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not fi... |
| CVE-2022-45770 | HIGH | 7.8 | 0.6% | Jan 26, 2023 | Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalat... |
| CVE-2022-44264 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path. |
| CVE-2022-44263 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | Dentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control. |
| CVE-2022-41029 | HIGH | 7.2 | 2.2% | Jan 26, 2023 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now